Yoast Duplicate Post through 4.6 inserts an unescaped post title and permalink into the Classic Editor scheduled republish notice. Attackers can schedule a republish copy with a crafted title to execute script when an administrator views the resulting notice.
Project Subscriptions
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 10 Jun 2026 23:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Wordpress
Wordpress wordpress |
|
| Vendors & Products |
Wordpress
Wordpress wordpress |
Wed, 10 Jun 2026 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Yoast Duplicate Post through 4.6 inserts an unescaped post title and permalink into the Classic Editor scheduled republish notice. Attackers can schedule a republish copy with a crafted title to execute script when an administrator views the resulting notice. | |
| Title | Yoast Duplicate Post through 4.6 Stored Cross-Site Scripting via Scheduled Republish Notice | |
| First Time appeared |
Duplicate Post Project
Duplicate Post Project duplicate Post |
|
| Weaknesses | CWE-79 | |
| CPEs | cpe:2.3:a:duplicate_post_project:duplicate_post:*:*:*:*:*:wordpress:*:* | |
| Vendors & Products |
Duplicate Post Project
Duplicate Post Project duplicate Post |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-06-10T20:39:44.745Z
Reserved: 2026-06-10T17:16:10.427Z
Link: CVE-2026-53740
No data.
Status : Received
Published: 2026-06-10T22:17:02.367
Modified: 2026-06-10T22:17:02.367
Link: CVE-2026-53740
No data.
OpenCVE Enrichment
Updated: 2026-06-10T23:00:20Z
Weaknesses